CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,231
Total CVEs
124
Critical
1,304
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
245
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 87
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 44

All Injection CVEs (2,231)

CVE-2025-2658
7.3

This critical SQL injection vulnerability in PHPGurukul Online Security Guards Hiring System 1.0 allows attackers to execute arbitrary SQL commands vi...

Mar 23, 2025
CVE-2025-2657
7.3

A critical SQL injection vulnerability in projectworlds Apartment Visitors Management System 1.0 allows remote attackers to execute arbitrary SQL comm...

Mar 23, 2025
CVE-2025-2655
7.3

This SQL injection vulnerability in SourceCodester AC Repair and Services System 1.0 allows attackers to manipulate database queries through the ID pa...

Mar 23, 2025
CVE-2025-2656
7.3

A critical SQL injection vulnerability in PHPGurukul Zoo Management System 2.1 allows attackers to manipulate database queries through the username pa...

Mar 23, 2025
CVE-2025-2654
7.3

This critical SQL injection vulnerability in SourceCodester AC Repair and Services System 1.0 allows remote attackers to manipulate database queries v...

Mar 23, 2025
CVE-2025-2649
7.3

This critical SQL injection vulnerability in PHPGurukul Doctor Appointment Management System 1.0 allows attackers to execute arbitrary SQL commands th...

Mar 23, 2025
CVE-2025-2648
7.3

This critical SQL injection vulnerability in PHPGurukul Art Gallery Management System 1.0 allows remote attackers to execute arbitrary SQL commands vi...

Mar 23, 2025
CVE-2025-2647
7.3

This critical SQL injection vulnerability in PHPGurukul Art Gallery Management System 1.0 allows attackers to execute arbitrary SQL commands through t...

Mar 23, 2025
CVE-2025-2646
7.3

This critical SQL injection vulnerability in PHPGurukul Art Gallery Management System 1.0 allows remote attackers to execute arbitrary SQL commands vi...

Mar 23, 2025
CVE-2025-2644
7.3

This critical SQL injection vulnerability in PHPGurukul Art Gallery Management System 1.0 allows remote attackers to execute arbitrary SQL commands vi...

Mar 23, 2025
CVE-2025-2643
7.3

This critical SQL injection vulnerability in PHPGurukul Art Gallery Management System 1.0 allows attackers to manipulate database queries through the ...

Mar 23, 2025
CVE-2025-2641
7.3

This critical SQL injection vulnerability in PHPGurukul Art Gallery Management System 1.0 allows attackers to manipulate database queries through the ...

Mar 23, 2025
CVE-2025-2640
7.3

This critical SQL injection vulnerability in PHPGurukul Doctor Appointment Management System 1.0 allows remote attackers to execute arbitrary SQL comm...

Mar 23, 2025
CVE-2025-2472
7.3

This critical SQL injection vulnerability in PHPGurukul Apartment Visitors Management System 1.0 allows attackers to execute arbitrary SQL commands th...

Mar 18, 2025
CVE-2025-2473
7.3

This critical SQL injection vulnerability in PHPGurukul Company Visitor Management System 2.0 allows attackers to manipulate database queries through ...

Mar 18, 2025
CVE-2025-2391
7.3

A critical SQL injection vulnerability in Blood Bank Management System 1.0 allows attackers to execute arbitrary SQL commands via the admin login page...

Mar 17, 2025
CVE-2025-2387
7.3

This critical SQL injection vulnerability in SourceCodester Online Food Ordering System 2.0 allows remote attackers to execute arbitrary SQL commands ...

Mar 17, 2025
CVE-2025-2385
7.3

CVE-2025-2385 is a critical SQL injection vulnerability in Modern Bag 1.0's login.php file that allows attackers to manipulate database queries throug...

Mar 17, 2025
CVE-2025-2386
7.3

This critical SQL injection vulnerability in PHPGurukul Local Services Search Engine Management System 1.0 allows remote attackers to execute arbitrar...

Mar 17, 2025
CVE-2025-2383
7.3

This critical SQL injection vulnerability in PHPGurukul Doctor Appointment Management System 1.0 allows attackers to execute arbitrary SQL commands th...

Mar 17, 2025
CVE-2025-2381
7.3

This critical SQL injection vulnerability in PHPGurukul Curfew e-Pass Management System 1.0 allows remote attackers to execute arbitrary SQL commands ...

Mar 17, 2025
CVE-2025-2382
7.3

This critical SQL injection vulnerability in PHPGurukul Online Banquet Booking System 1.0 allows attackers to execute arbitrary SQL commands via the s...

Mar 17, 2025
CVE-2025-2380
7.3

This critical SQL injection vulnerability in PHPGurukul Apartment Visitors Management System 1.0 allows attackers to manipulate database queries throu...

Mar 17, 2025
CVE-2025-2379
7.3

This critical SQL injection vulnerability in PHPGurukul Apartment Visitors Management System 1.0 allows remote attackers to execute arbitrary SQL comm...

Mar 17, 2025
CVE-2025-2378
7.3

This critical SQL injection vulnerability in PHPGurukul Medical Card Generation System 1.0 allows remote attackers to execute arbitrary SQL commands v...

Mar 17, 2025
CVE-2025-2372
7.3

This critical SQL injection vulnerability in PHPGurukul Human Metapneumovirus Testing Management System 1.0 allows remote attackers to execute arbitra...

Mar 17, 2025
CVE-2025-2362
7.3

This critical SQL injection vulnerability in PHPGurukul Pre-School Enrollment System 1.0 allows attackers to manipulate database queries via the mobnu...

Mar 17, 2025
CVE-2025-2353
7.3

This critical SQL injection vulnerability in VAM Virtual Airlines Manager allows remote attackers to execute arbitrary SQL commands through manipulate...

Mar 17, 2025
CVE-2025-2351
7.3

A critical SQL injection vulnerability in DayCloud StudentManage 1.0 allows remote attackers to execute arbitrary SQL commands via the query parameter...

Mar 16, 2025
CVE-2025-2118
7.3

This critical SQL injection vulnerability in Quantico Tecnologia PRMV 6.48 allows attackers to execute arbitrary SQL commands via the username paramet...

Mar 9, 2025
CVE-2025-2113
7.3

This critical SQL injection vulnerability in AT Software Solutions ATSVD allows attackers to execute arbitrary SQL commands through the 'Esqueceu a se...

Mar 9, 2025
CVE-2025-2088
7.3

This critical SQL injection vulnerability in PHPGurukul Pre-School Enrollment System allows attackers to manipulate database queries through the profi...

Mar 7, 2025
CVE-2025-2066
7.3

This critical SQL injection vulnerability in Life Insurance Management System 1.0 allows attackers to execute arbitrary SQL commands via the agent_id ...

Mar 7, 2025
CVE-2025-2067
7.3

This critical SQL injection vulnerability in Life Insurance Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'k...

Mar 7, 2025
CVE-2025-2063
7.3

A critical SQL injection vulnerability in Life Insurance Management System 1.0 allows attackers to manipulate database queries via the nominee_id para...

Mar 7, 2025
CVE-2025-2064
7.3

A critical SQL injection vulnerability in Life Insurance Management System 1.0 allows attackers to manipulate database queries via the recipt_no param...

Mar 7, 2025
CVE-2025-2065
7.3

A critical SQL injection vulnerability in Life Insurance Management System 1.0 allows remote attackers to manipulate database queries via the agent_id...

Mar 7, 2025
CVE-2025-2062
7.3

A critical SQL injection vulnerability in Life Insurance Management System 1.0 allows attackers to manipulate database queries via the client_id param...

Mar 7, 2025
CVE-2025-2060
7.3

A critical SQL injection vulnerability exists in PHPGurukul Emergency Ambulance Hiring Portal 1.0, specifically in the /admin/admin-profile.php file's...

Mar 7, 2025
CVE-2025-2057
7.3

This critical SQL injection vulnerability in PHPGurukul Emergency Ambulance Hiring Portal 1.0 allows remote attackers to execute arbitrary SQL command...

Mar 7, 2025
CVE-2025-2058
7.3

This critical SQL injection vulnerability in PHPGurukul Emergency Ambulance Hiring Portal 1.0 allows remote attackers to execute arbitrary SQL command...

Mar 7, 2025
CVE-2025-2059
7.3

This critical SQL injection vulnerability in PHPGurukul Emergency Ambulance Hiring Portal 1.0 allows attackers to manipulate database queries through ...

Mar 7, 2025
CVE-2025-2050
7.3

This critical SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System 3.3 allows attackers to manipulate databa...

Mar 7, 2025
CVE-2025-2030
7.3

This critical SQL injection vulnerability in Seeyon Zhiyuan Interconnect FE Collaborative Office Platform allows remote attackers to execute arbitrary...

Mar 6, 2025
CVE-2025-1966
7.3

A critical SQL injection vulnerability exists in PHPGurukul Pre-School Enrollment System 1.0, specifically in the /admin/index.php file's username par...

Mar 5, 2025
CVE-2025-1964
7.3

This critical SQL injection vulnerability in Online Hotel Booking 1.0 allows remote attackers to execute arbitrary SQL commands via the 'checkin' para...

Mar 5, 2025
CVE-2025-1963
7.3

This critical SQL injection vulnerability in Projectworlds Online Hotel Booking 1.0 allows remote attackers to execute arbitrary SQL commands via the ...

Mar 5, 2025
CVE-2025-1959
7.3

A critical SQL injection vulnerability exists in Codezips Gym Management System 1.0, specifically in the /change_s_pwd.php file. Attackers can manipul...

Mar 4, 2025
CVE-2025-1956
7.3

A critical SQL injection vulnerability in code-projects Shopping Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the password...

Mar 4, 2025
CVE-2025-1954
7.3

This critical SQL injection vulnerability in PHPGurukul Human Metapneumovirus Testing Management System 1.0 allows remote attackers to execute arbitra...

Mar 4, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,231 CVEs classified as CWE-74, with 124 rated critical and 1,304 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free